vulnerable tagDiv Composer 5.0 – Reflected Cross-Site Scripting via envato_code

Posted in: Newspaper
Post count: 77

Hi,

We keep getting this vulnerabilaty warning from WP Toolkit (Plesk VPS server) (severity is medium). We have the latest version of td composer (5.1) The message is:

tagDiv Composer <= 5.0 – Reflected Cross-Site Scripting via envato_code[]
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_register_forum_user function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Copyright text: Wordfence

Is this something we need to address ourselve, is it something in the code your team needs to fix, or is it a false positive?

If have read older posts about this kind of message on Reflected Cross-Site Scripting, but in all of them you told an update should fix it next time. It’s about a few next times further however, so I am curious if this is a returning vulnerabilaty or just an over excited Wordfence producing a non-issue?

Thanks in advance for your time and efforts regarding this issue.

Post count: 9544

Probably a bug in Plesk toolbox; since if you’re running 5.1, it probably should not give you warning about “hey, don’t use versions below 5.0).
I stopped using the toolbox on Plesk, myself.
(*it could also be the toolbox needs to be updated from your hosting panel).

  • This reply was modified 1 year by simchris.
Post count: 21065

Hello!

There could be some false-positive warnings. I will add this issue into our investigation list.

Thank you!

Post count: 77

Thanks simchris for making an obvious but valid point regarding the versions mentioned. I will let our tech guy investigate if the update went correctly and if the Plesk toolbox is still needed or just creates a lot of ‘noise’.

Bettina thanks for adding it to your investigation list. Besides the stated above to simchris, we will ingnore this for now.

Post count: 54

Please, any update on this? Still appear in version 5.4.3.1 in Plesk
Thanks

Post count: 21065

Hello @asisrodriguez!

We already solved this issue regarding the theme.

Thank you!

Post count: 54

Thanks but still appear in my Plesk 🙁 sorry, I see is a Toolkit bug…

Viewing 7 posts - 1 through 7 (of 7 total)
The forum ‘Newspaper’ is closed to new topics and replies.